Back

CVE-2002-0661

Directory traversal vulnerability in Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to read arbitrary files and execute commands via .. (dot dot) sequences containing \ (backslash) characters.

Published: Aug 12, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (12)

Vendor Product Version
apache http_server 2.0
apache http_server 2.0.28
apache http_server 2.0.28
apache http_server 2.0.28
apache http_server 2.0.32
apache http_server 2.0.32
apache http_server 2.0.34
apache http_server 2.0.35
apache http_server 2.0.36
apache http_server 2.0.37
apache http_server 2.0.38
apache http_server 2.0.39

GitHub Security Advisory GHSA-cjcj-mxqx-222g

Directory traversal vulnerability in Apache 2.0 through 2.0.39 on Windows, OS2, and Netware...

References (34)

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 69.70%

Top 1% most likely to be exploited

Threat Score 50.9 / 100

Data Sources

NVD EPSS GitHub